PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #206
You have stored company approved compute images in a single Google Cloud project that is used as an image repository. This project is protected with VPC Service Controls and exists in the perimeter…
The correct answer is B. 1. Update the perimeter. VPC Service Controls perimeters block access to and from external resources by default. To allow an external Google Cloud organization's disk image to be accessed from within the perimeter, you must update the service perimeter's ingress/egress rules to explicitly permit that…
Question
Options
- AAllow the external project by using the organizational policy,
- B
- Update the perimeter.
- C
- Update the perimeter.
- D
- Update the perimeter.
How the community answered
(32 responses)- A3% (1)
- B81% (26)
- C9% (3)
- D6% (2)
Explanation
VPC Service Controls perimeters block access to and from external resources by default. To allow an external Google Cloud organization's disk image to be accessed from within the perimeter, you must update the service perimeter's ingress/egress rules to explicitly permit that external resource. This involves adding an ingress rule that allows the specific external project or image resource through the perimeter boundary. Option A (organizational policy) can restrict which images are used but does not override VPC Service Controls boundaries. Options C and D are described similarly to B in truncated form, but the canonical approach is updating the perimeter ingress policy to allow the external resource - which corresponds to answer B.
Topics
Community Discussion
No community discussion yet for this question.